Current - Issue
Review Article
Behavioral Red Teaming: A Systematic Literature Review of Human Vulnerability Assessment in Cybersecurity
Pranjal Upadhyay1
1 School of IT, AI & Cyber Security, Rashtriya Raksha University, Gujarat, India.
Published Online: May-August 2026
Pages: 868-878
Cite this article
↗ https://www.doi.org/10.59256/indjcst.20260502094References
1. Hadnagy, C. (2018). Social engineering: The science of human hacking. wiley publ.
2. Gass, R. H., & Seiter, J. S. (2022). Persuasion: Social influence and compliance gaining. Routledge.
3. Wilson, M., & Hash, J. (2003). National Institute of Standards and Technology (NIST), Building an Information Technology Security
Awareness and Training Program (NIST SP 800-50). US Department of Commerce, Washington, DC.
4. Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer security incident handling guide. NIST Special Publication, 800(61),
1-147.
5. Spring, J. M., & Illari, P. (2021). Review of human decision-making during computer security incident analysis. Digital Threats: Research
and Practice, 2(2), 1-47.
6. RISK, C. (2021). Risk management framework. COPRPORATE REPORT.
7. Landscape, E. T. (2023). European Union Agency for Cybersecurity (ENISA), 2023. URL: https://www. enisa. europa. eu/topics/cyber-
threats/threat-landscape (date of access: 8.10. 2025).
8. Kaczmarczyk, B. (2024). Cyberattacks/incidents and responding to them.
9. Omotade, A. L., Ghimire, A., & Sultan, M. (2025, October). Cybersecurity, Data Privacy, and Information Security Management. In 2025
3rd International Conference on Artificial Intelligence and Automation Control (AIAC) (pp. 27-33). IEEE.
10. Nissinen, M. (2025). Strategy-Driven Information Security Framework for Enhancing Situational Awareness.
11. Kumar, N., & Patel, N. M. (2025). Social engineering attack in the era of generative AI. International Journal for Research in Applied
Science and Engineering Technology, 13(1), 1737-1747.
12. Kumar, N. (2026). Cyber Security Threats and Challenges in CPS. AI and Cyber Security in Cyber-Physical Systems, 53-78.
13. Kumar, N., Deshkar, D., & Patel, N. (2025). Fine-Tuning Language Models for Social Engineering: A Technical Feasibility Study. In
Proceedings of the IEEE 7th International Conference on Computing, Communication and Automation (ICCCA) (pp. 1–6).
14. Deshkar, D. (2025). Quantitative and Computational Mathematical Analysis of Gen-AI-Facilitated Social Engineering Threats. International
Journal of Applied Mathematics, 38(10s), 2159–2179.
15. Kumar, N., Deshkar, D., De, S., Saini, A., Kania, R. P., & Kasera, C. (2025). A Comprehensive Analysis of Security Flaws and Attack
Vectors in Artificial Intelligence–Powered Brain–Computer Interfaces. Vascular and Endovascular Review, 8(6s), 106–121.
16. Davis, G. E. (2025). CYBER AND DATA PRIVACY INSURANCE IN 2025. Brief, 54(2).
17. LAKHTIONOVA, A. (2025). GLOBAL CYBERSECURITY MARKET 2017–2029: DYNAMICS, STRUCTURE, CHALLENGES AND
KEY PLAYERS. Society. Economy. Digitalization, 1(4), 61-75.
18. Gazzola, P., Amelio, S., Pavione, E., & Marubini, F. (2026). The centrality of cybersecurity: business models, competitive strategies and
sustainability practices. Business Process Management Journal, 1-24.
19. Van Than, V. (2025). Future-Back Threat Modeling: A Foresight-Driven Security Framework. arXiv preprint arXiv:2511.16088.
20. Konerza, C. (2025). Aviation Cybersecurity and Third-Party Software Service Providers: Do Companies Like CrowdStrike Get a Free Pass
to Create Cyber Vulnerabilities?. Journal of Air Law and Commerce, 90(4), 453.
21. Mc Cabe, M., & Houmb, S. H. (2026). Enhancing the MITRE ATT&CK® Framework for Cyber-Physical Systems Using Insights from
Advanced Persistent Threats. Applied Sciences, 16(4), 1815.
22. Pollini, A., Callari, T. C., Tedeschi, A., Ruscio, D., Save, L., Chiarugi, F., & Guerri, D. (2022). Leveraging human factors in cybersecurity:
an integrated methodological approach. Cognition, Technology & Work, 24(2), 371-390.
23. Peca, L., & Tsurcanu, D. (2025). Reducing cyber risk through a human–centred approach. Journal of Engineering Science, (1), 18-31.
24. Acquisti, A., Brandimarte, L., & Loewenstein, G. (2015). Privacy and human behavior in the age of information. Science, 347(6221), 509-
514.
25. Schneier, B. (2015). Secrets and lies: digital security in a networked world. John Wiley & Sons.
26. Kahneman, D. Thinking, Fast and Slow. New York, NY, USA: Farrar, Straus and Giroux; 2011.
27. Thaler, R. H., & Sunstein, C. R. (2009). Nudge: Improving decisions about health, wealth, and happiness. Penguin.
28. Furnell, S., & Thomson, K. L. (2009). From culture to disobedience: Recognising the varying user acceptance of IT security. Computer
fraud & security, 2009(2), 5-10.
29. Workman, M. (2008). Wisecrackers: A theory‐grounded investigation of phishing and pretext social engineering threats to information
security. Journal of the American society for information science and technology, 59(4), 662-674.
30. Vishwanath, A., Herath, T., Chen, R., Wang, J., & Rao, H. R. (2011). Why do people get phished? Testing individual differences in phishing
vulnerability within an integrated, information processing model. Decision Support Systems, 51(3), 576-586.
31. Cranor, L. F. (2008). A framework for reasoning about the human in the loop.
32. Weatherald, N. A. (2022). Reinventing the blurry oval: Practitioner perceptions of deepfakes as a tool for anonymisation in documentary
film and video journalism.
33. Bonneau, J. (2012, May). The science of guessing: analyzing an anonymized corpus of 70 million passwords. In 2012 IEEE symposium on
security and privacy (pp. 538-552). IEEE.
34. Shostack, A. (2014). Threat modeling: Designing for security. John wiley & sons.
35. Sotira, N. (2018). The human factor in cyber security. Cyber Security: A Peer-Reviewed Journal, 1(4), 326-330.
36. Aljohani, M., Furnell, S., Carpent, X., & Gervassis, N. (2025, June). Examining the Influence of Cultural Diversity in Cybersecurity Culture.
In European Interdisciplinary Cybersecurity Conference (pp. 151-165). Cham: Springer Nature Switzerland.
2. Gass, R. H., & Seiter, J. S. (2022). Persuasion: Social influence and compliance gaining. Routledge.
3. Wilson, M., & Hash, J. (2003). National Institute of Standards and Technology (NIST), Building an Information Technology Security
Awareness and Training Program (NIST SP 800-50). US Department of Commerce, Washington, DC.
4. Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer security incident handling guide. NIST Special Publication, 800(61),
1-147.
5. Spring, J. M., & Illari, P. (2021). Review of human decision-making during computer security incident analysis. Digital Threats: Research
and Practice, 2(2), 1-47.
6. RISK, C. (2021). Risk management framework. COPRPORATE REPORT.
7. Landscape, E. T. (2023). European Union Agency for Cybersecurity (ENISA), 2023. URL: https://www. enisa. europa. eu/topics/cyber-
threats/threat-landscape (date of access: 8.10. 2025).
8. Kaczmarczyk, B. (2024). Cyberattacks/incidents and responding to them.
9. Omotade, A. L., Ghimire, A., & Sultan, M. (2025, October). Cybersecurity, Data Privacy, and Information Security Management. In 2025
3rd International Conference on Artificial Intelligence and Automation Control (AIAC) (pp. 27-33). IEEE.
10. Nissinen, M. (2025). Strategy-Driven Information Security Framework for Enhancing Situational Awareness.
11. Kumar, N., & Patel, N. M. (2025). Social engineering attack in the era of generative AI. International Journal for Research in Applied
Science and Engineering Technology, 13(1), 1737-1747.
12. Kumar, N. (2026). Cyber Security Threats and Challenges in CPS. AI and Cyber Security in Cyber-Physical Systems, 53-78.
13. Kumar, N., Deshkar, D., & Patel, N. (2025). Fine-Tuning Language Models for Social Engineering: A Technical Feasibility Study. In
Proceedings of the IEEE 7th International Conference on Computing, Communication and Automation (ICCCA) (pp. 1–6).
14. Deshkar, D. (2025). Quantitative and Computational Mathematical Analysis of Gen-AI-Facilitated Social Engineering Threats. International
Journal of Applied Mathematics, 38(10s), 2159–2179.
15. Kumar, N., Deshkar, D., De, S., Saini, A., Kania, R. P., & Kasera, C. (2025). A Comprehensive Analysis of Security Flaws and Attack
Vectors in Artificial Intelligence–Powered Brain–Computer Interfaces. Vascular and Endovascular Review, 8(6s), 106–121.
16. Davis, G. E. (2025). CYBER AND DATA PRIVACY INSURANCE IN 2025. Brief, 54(2).
17. LAKHTIONOVA, A. (2025). GLOBAL CYBERSECURITY MARKET 2017–2029: DYNAMICS, STRUCTURE, CHALLENGES AND
KEY PLAYERS. Society. Economy. Digitalization, 1(4), 61-75.
18. Gazzola, P., Amelio, S., Pavione, E., & Marubini, F. (2026). The centrality of cybersecurity: business models, competitive strategies and
sustainability practices. Business Process Management Journal, 1-24.
19. Van Than, V. (2025). Future-Back Threat Modeling: A Foresight-Driven Security Framework. arXiv preprint arXiv:2511.16088.
20. Konerza, C. (2025). Aviation Cybersecurity and Third-Party Software Service Providers: Do Companies Like CrowdStrike Get a Free Pass
to Create Cyber Vulnerabilities?. Journal of Air Law and Commerce, 90(4), 453.
21. Mc Cabe, M., & Houmb, S. H. (2026). Enhancing the MITRE ATT&CK® Framework for Cyber-Physical Systems Using Insights from
Advanced Persistent Threats. Applied Sciences, 16(4), 1815.
22. Pollini, A., Callari, T. C., Tedeschi, A., Ruscio, D., Save, L., Chiarugi, F., & Guerri, D. (2022). Leveraging human factors in cybersecurity:
an integrated methodological approach. Cognition, Technology & Work, 24(2), 371-390.
23. Peca, L., & Tsurcanu, D. (2025). Reducing cyber risk through a human–centred approach. Journal of Engineering Science, (1), 18-31.
24. Acquisti, A., Brandimarte, L., & Loewenstein, G. (2015). Privacy and human behavior in the age of information. Science, 347(6221), 509-
514.
25. Schneier, B. (2015). Secrets and lies: digital security in a networked world. John Wiley & Sons.
26. Kahneman, D. Thinking, Fast and Slow. New York, NY, USA: Farrar, Straus and Giroux; 2011.
27. Thaler, R. H., & Sunstein, C. R. (2009). Nudge: Improving decisions about health, wealth, and happiness. Penguin.
28. Furnell, S., & Thomson, K. L. (2009). From culture to disobedience: Recognising the varying user acceptance of IT security. Computer
fraud & security, 2009(2), 5-10.
29. Workman, M. (2008). Wisecrackers: A theory‐grounded investigation of phishing and pretext social engineering threats to information
security. Journal of the American society for information science and technology, 59(4), 662-674.
30. Vishwanath, A., Herath, T., Chen, R., Wang, J., & Rao, H. R. (2011). Why do people get phished? Testing individual differences in phishing
vulnerability within an integrated, information processing model. Decision Support Systems, 51(3), 576-586.
31. Cranor, L. F. (2008). A framework for reasoning about the human in the loop.
32. Weatherald, N. A. (2022). Reinventing the blurry oval: Practitioner perceptions of deepfakes as a tool for anonymisation in documentary
film and video journalism.
33. Bonneau, J. (2012, May). The science of guessing: analyzing an anonymized corpus of 70 million passwords. In 2012 IEEE symposium on
security and privacy (pp. 538-552). IEEE.
34. Shostack, A. (2014). Threat modeling: Designing for security. John wiley & sons.
35. Sotira, N. (2018). The human factor in cyber security. Cyber Security: A Peer-Reviewed Journal, 1(4), 326-330.
36. Aljohani, M., Furnell, S., Carpent, X., & Gervassis, N. (2025, June). Examining the Influence of Cultural Diversity in Cybersecurity Culture.
In European Interdisciplinary Cybersecurity Conference (pp. 151-165). Cham: Springer Nature Switzerland.
Related Articles
2026
Artificial Intelligence in Learning and Teaching
2026
Admin Assist: An AI – Driven Configuration and Orchestration for Enterprise Application
2026
Enhancing Blood Group Identification using pigeon inspired optimization: An Innovative Approach
2026
Eco-Genius: Power Up Smart, Power Down Waste
2026
Crowd-Sourced Disaster Response and Rescue Assistant
2026
Unveiling Deepfake Detection Using Vision Transformers: A Survey and Experimental Study
Share Article
Or copy link
https://www.indjcst.com/archives/behavioral-red-teaming-a-systematic-literature-review-of-human-vulnerability-assessment-in-cybersecurity
*Instagram doesn't support direct link sharing from web. Copy the link and share it in your Instagram story or post.